3 ms·
It took me a non-zero amount of time researching to discover all that--it's not like the GitHub information spells that out as an option.
by follower 3y ago
It took me a non-zero amount of time researching to discover all that--it's not like the GitHub information spells that out as an option.
- mxmlnkn 3y agoThat is true and I mentioned oathtool in order to spread my knowledge. At least this trick can be used for almost any 2FA method. And, more and more keep bothering me with this, e.g., when trying to read Google mails via Thunderbird, you have to create 2FA in order to create an application token that can be used with Thunderbird. So many tokens and passwords. It really keeps getting on my nerves and I don't trust things that are locked onto my smartphone because it might get lost. The first reflex was to simply save the QR code, but then I also wanted to know how I could use it without Google authenticator and so I found oathtool. And as can be seen from the two necessary command line arguments, the default oathtool invocation also didn't work out of the box. To be fair, Google and also Github, both, provide recovery codes, which can be used if you loose your 2FA device. But now you have basically 3 "passwords", two Yubikeys, plus your associated mail address, all of which you have to remember or store. All of this just for a single account out of a thousand, which you aggregate over a decade or more.